Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Shell tools stop offering the sandbox escape when unsandboxed commands are disabled

When unsandboxed commands are turned off, Bash and PowerShell no longer offer Claude the dangerouslyDisableSandbox option

Group of 2 You'll notice Improvements
JSON All of v2.1.284
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release

Unclear Which setting a user changes to disallow unsandboxed commands is not confirmed.

What

The sandbox is a restricted environment that shell commands run inside, which limits what they can reach. Each tool Claude can use comes with a schema, a description of the inputs Claude is allowed to fill in. The Bash and PowerShell tools have an input called dangerouslyDisableSandbox, which asks to run a command outside the sandbox.

The schemas are now trimmed to match your sandbox settings:

  • dangerouslyDisableSandbox is removed from the Bash and PowerShell input schemas when the sandbox settings report unsandboxedCommandsDisabled.
  • run_in_background is still removed separately from the Bash schema when background tasks are disabled.
  • For another schema, the same trimming also removes run_in_background and _simulatedSedEdit.
  • The setup that turns off both background tasks and unsandboxed commands is applied where the tool schemas are listed.

Before this release, the schemas kept dangerouslyDisableSandbox in these cases. It was only listed as an input that would be refused if Claude used it.

Why

If your setup does not allow commands to run outside the sandbox, Claude is no longer shown an option it cannot use. It therefore cannot try to escape the sandbox and then be refused.

Read from
Names in the bundledangerouslyDisableSandboxrun_in_background
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up dangerouslyDisableSandbox, on Configure the sandboxed Bash tool. The unsandboxed retry is an escape hatch for commands that fail inside the sandbox, such as tools that are incompatible with it. When the sandbox blocks a network connection, Claude Code names the denied host in the command's result, so Cl… sandboxing see the edit
Added since A small documentation edit on Agent SDK reference - Python touched a line naming run_in_background after this was published. "timeout": int | None, # Milliseconds. Foreground: capped at 600000 by default, higher values are clamped. With run_in_background (Claude Code v2.1.285 or later): the background time limit, 1800000 when omitted, capped at 7200000 unless ra… agent-sdk/python see the edit
Confirmed since Anthropic's documentation has since written up run_in_background, on Claude Code changelog. * Changed background Bash and PowerShell commands to stop after a time limit (their `timeout` with `run_in_background`, default 30 min, max 2 h); Claude is notified when one is stopped changelog see the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhich setting a user changes to disallow unsandboxed commands is not confirmed.
Anthropic's documentation agreesAnthropic's documentation has since written up run_in_background, on Claude Code changelog.

See this entry in the whole of v2.1.284 →

Feedback